Splunk Flashcards
Machine data makes up for more than ___% of the data accumulated by organizations.
90%
Machine data is always structured.
False
Machine data is only generated by web servers.
False
What are the three main processing components of Splunk?
Forwarders, Search Heads, & Indexers
Search strings are sent from the _________.
Search Heads
In most Splunk deployments, ________ serve as the primary way data is supplied for indexing.
Forwarders
Which function is not a part of a single instance deployment?
Clustering
A single-instance deployment of Splunk Enterprise handles:
Indexing Search, Parsing, & Input
What are the three main default roles in Splunk Enterprise?
Admin, User, & Power
Which apps ship with Splunk Enterprise?
Home App & Search & Reporting
This role will only see their own knowledge objects and those that have been shared with them.
User
_________ define what users can do in Splunk.
Roles
The password for a newly installed Splunk instance is:
Created when you install Splunk Enterprise
Files indexed using the upload input option get indexed _____.
Once
Splunk uses ________ to categorize the type of data being indexed.
Sourcetype
The monitor input option will allow you to continuously monitor files.
True
Splunk knows where to break the event, where the time stamp is located and how to automatically create field value pairs using these.
Source Type
In most production environments, _______ will be used as the source of data input.
Forwarders
Events are always returned in chronological order.
False
Which following search mode toggles behavior based on the type of search being run?
Smart
What is the order of evaluation for Boolean operations in Splunk?
NOT, OR, & AND
When zooming in on the event timeline, a new search is run.
False
Shared search jobs remain active for _______ by default.
7 days
Field names are ________.
Case sensitive
What attributes describe the circled field below?
It contains 4 values and a string value
Field values are case sensitive
False
Which is not a comparison operator in Splunk?
?=
Wildcards cannot be used with field searches.
False
What is the most efficient way to filter events in Splunk?
By time
Time to search can only be set by the time range picker.
False